In my earlier post, I explained what happens when you use Copy To and Move To.

I really like using it, but of course there are some risks too, especially because it is very easy to do.
I have already encountered the first casualties and I assume many more will follow.

So here are some things that I think are a tad dangerous:

Even people with only “Read” permissions can Copy your content to a site they have more permissions to, or to their OneDrive. What does this do for “one version of the truth”?

It is now very easy to Copy confidential content to a location with a completely different audience.

People with Contribute or Edit in your site can Move documents to another site and delete them from your site.
This has been a recent issue with one of my users. He reported that he had lost a large part of his site’s content and did not know what had happened. Fortunately I found his (200+) documents in the Recycle Bin. They had all been deleted by the same person, in a time span of about 5 minutes. I still do not know if that person had really used the Move option, but it is plausible.

There is no way for you, as a site owner, to see if content has been Copied to a different site.
You can see in the Document Information Pane if people have deleted content. You could also set an Alert for Deleted Items, so you know quickly if an unexpected large number of documents has been deleted and you can ask the deleter if they have Moved content. But for Copy…no option.

As far as I know, there is no option for the site collection admins to see what has happened, except when documents that have been deleted are mentioned in the Document Information Pane or show up in the Recycle Bin. (Please let me know if you have found how to do it – a third-party tool perhaps?)

You can lose metadata and versions if the target contains fewer than the source. With the new versioning settings the latter will probably not cause many issues.

You can break links as I found out recently. I moved some documents around because I wanted to combine some libraries and I had forgotten these were accessed from Promoted Links. Duh! 🙂

How to counteract:

1. Give everyone only the permissions they really need

Making sure every person has the correct permissions is getting more and more important.
With the defaults for sharing and access requests set to give people “Contribute” or “Edit” permissions accidents with Copy or Move are more likely to happen.
Delve, that shows you potentially interesting information that you have access to, makes this part of site ownership even more important!
I often use an extra permissions set called “Contribute without Delete” which means people can Read, Add and Edit but only the Site Owner can delete content. That reduces the likelihood of content disappearing.

2. Inform users how Copy To and Move To work

If your users know how this works, they may be more aware what they are doing. Perhaps this picture helps to convey quickly what happens.

3. Inform users of the confidentiality of your content

Always make your site’s audience aware of the confidentiality status of your content. Not everyone may realize that some content (such as new brand names, prices or competitor info) may damage your company, should it fall into the wrong hands.
Tell your audience which content should not be shared and copied, and what the consequences could be if they do, both for the company and perhaps even for themselves.

4. Set Alerts for deleted items

You may want to set an Alert for content that is deleted, so you are warned when you see an unexpected large amount of deletions, for instance. As you can not restore the content someone else has deleted, contact your support team as quickly as possible to restore the content.

Of course I am curious to learn which issues you have encountered, and how you have solved those!

2 thoughts on “7 Risks of Copy To and Move To (in SharePoint Online)”

The Security & Compliance Center may help with tracking down what has happened in some of these cases, but by then the horse is out of the barn and frolicking in the meadow.

I’m going to share your post with a couple folks at Microsoft, as I think you raise some important issues here. (As usual, if anyone thinks something should work differently, UserVoice is the place to lodge it.)

Hi Marc, I appreciate your efforts. I really like the functionality, and it is not very different from using Content and Structure or Open in Explorer, but as it is so easy to do, needs fewer permissions (C&S needs Contribute at least) and keeps the original data, I think this will be very popular and may lead to issues. Not sure if it needs to work differently, but I would appreciate a way that support teams could see if content was copied or moved, to solve issues.